Description
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.
Published: 2020-12-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-9390 An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.
Ubuntu USN Ubuntu USN USN-6259-1 Open-iSCSI vulnerabilities
History

No history.

Subscriptions

Contiki-os Contiki
Open-iscsi Project Open-iscsi
Siemens Sentron 3va Com100 Sentron 3va Com100 Firmware Sentron 3va Com800 Sentron 3va Com800 Firmware Sentron 3va Dsp800 Sentron 3va Dsp800 Firmware Sentron Pac2200 Sentron Pac2200 Clp Sentron Pac2200 Clp Firmware Sentron Pac2200 Firmware Sentron Pac3200 Sentron Pac3200 Firmware Sentron Pac3200t Sentron Pac3200t Firmware Sentron Pac3220 Sentron Pac3220 Firmware Sentron Pac4200 Sentron Pac4200 Firmware
Uip Project Uip
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T13:53:17.554Z

Reserved: 2020-08-07T00:00:00.000Z

Link: CVE-2020-17437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-11T23:15:12.683

Modified: 2024-11-21T05:08:06.540

Link: CVE-2020-17437

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-12-09T00:00:00Z

Links: CVE-2020-17437 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses